This application requires Javascript for optimal performance.

McAfee.Remediation.Client.Enginecom.Dll.ActiveX.Access

Release Date

Nov 03, 2009

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attempt to exploit a code execution vulnerability in McAfee Remediation Agent.

The vulnerability is located in the "enginecom.dll" ActiveX control through misuse of the "DeleteSnapshot" method. It may allow remote attackers to execute arbitrary code in vulnerable systems.

Affected Products

McAfee Remediation Agent 4.5.0.41

Recommended Actions

Set the kill bit for the affected ActiveX control.
The progid of the affected ActiveX control is Enginecom.imagineLANEngine.1

Coverage

IPS
VCM

Reference: VID-17849